This Trojan may be downloaded by other malware/grayware/spyware from remote sites. It arrives as a component bundled with malware/grayware packages. It may be dropped by other malware.
It connects to a website to send and receive information.
File size: varies
File type: EXE
Memory resident: Yes
Initial samples received date: 06 Aug 2012
Arrival Details
This Trojan may be downloaded by other malware/grayware/spyware from remote sites.
It arrives as a component bundled with malware/grayware packages.
It may be dropped by the following malware:
Installation
This Trojan drops the following component file(s):
- {Malware Path}\ker.dll
- %Program Files%\WindowsZip\temp\Update\window.exe
- %Program Files%\WindowsZip\temp\0.txt
- %User Temp%\wuauclt.exe
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It creates the following folders:
- %Program Files%\WindowsZip\temp\Update
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
Autostart Technique
This Trojan modifies the following registry entry(ies) to enable its automatic execution at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
User Shell Folders
Common Startup = %Program Files%\WindowsZip\temp\Update
(Note: The default value data of the said registry entry is %ALLUSERSPROFILE%\Start Menu\Programs\Startup.)
HKEY_CURRENT_USER\Software\Microsoft\
Windows NT\CurrentVersion\Windows
load = %User Temp%\wuauclt.exe
(Note: The default value data of the said registry entry is "".)
Backdoor Routine
This Trojan connects to the following websites to send and receive information:
- http://{BLOCKED}va2018.narod2.ru
- http://{BLOCKED}z.yandex.ru
Information Theft
This Trojan sends the gathered information to the following site/s using credentials from its configuration file:
- http://www.{BLOCKED}hooservice.com/cgi-edk/tdw.cgi
Connect with us on
| | | |